This course contains the use of artificial intelligence.
Something specific happens about eight weeks after an engineering organisation hands agentic coding to everyone. Merged pull request volume roughly doubles. Everybody celebrates. And then the second number arrives: median time in review climbs, change failure rate creeps up, and a quarter later somebody in an audit asks who approved the change an agent wrote at two in the morning – and nobody can answer.
That is not an AI problem. It is a process problem. We got very good at making AI write code, and we left every stage around the code running at human speed.
This course rebuilds the lifecycle itself. It follows Anthropic’s AI-Native SDLC Playbook – six stages arranged as a loop rather than a line, where each stage ends by committing an artifact and the next stage begins by reading it. You will build the whole chain: an intent file, a spec file, a plan file, the diff and its tests, the pull request with its review findings, and the incident record that writes the next intent.
Every mechanism is built, not described. You will write a PreToolUse hook that blocks an edit and names the route to approval. You will interrogate Claude into a plan before a line of code exists. You will stand up an eval suite that regression-tests your agent’s configuration when a skill changes. You will write a review-policy file with a severity threshold and a nit cap. You will set a production gate that the agent may act up to and cannot pass. And you will wire statistical control bands so a 3-sigma breach diagnoses itself and files an intent file before anyone is paged.
Governance is treated as a first-class concern, not an afterthought. Every play in this course names what is enforced, what the evidence is, where it is logged and who approves. You will learn the single most expensive design error teams make – choosing the wrong strength of control – and the difference between a rule that holds and a sentence in a file that nobody enforces.
We work through one company the whole way. Meridian Pay is a 640-person B2B payments platform: FCA-authorised, DORA in scope for its EU entity, PCI-DSS on the cardholder path, SOC 2 and ISO 27001. It rolled Claude Code out to 90 engineers, doubled its PR volume, watched change failure rate go from 8% to 19%, and failed an internal audit because it could not evidence who approved agent-authored changes inside PCI scope. Its CTO has one quarter to fix it without giving the speed back. Every decision in this course is made against that constraint.
You will finish with artefacts, not notes. Templates for intent, spec, plan and review. A protected-path hook and a production-gate hook. An eval-suite starter. A control-band config. A leading/lagging metric pack with a baseline capture step. A gate-to-control mapping worksheet linking each gate to NIST SSDF, ISO/IEC 42001 and SOC 2. And a 90-day rollout plan you can defend to your leadership on Monday.
Thirty-five lectures, eight sections, five assignments and a final practice exam. Built for engineering leads, platform teams and anyone accountable for the speed and the evidence.


